4 ms·
Details of some 100M visitors to Thailand exposed online
- gnyman 5y agoAccording to comparitech[1] it is Yet Another Elastic database exposed. I do wonder a bit how the people at Elastic continues to defend not having authentication enforced by default. As of today, going to https://www.elastic.co/guide/en/elasticsearch/reference/current/getting-started.html https://www.elastic.co/guide/en/elasticsearch/reference/curr... and following their guide for a self hosted ES instance is probably the fastest way to have a data breach. Especially if you had a firewall like ufw in place and relied on it to not expose everything (because of dockers continued insistence on bypassing it [2]). [1] https://www.comparitech.com/blog/information-security/thai-traveler-data-leak/ https://www.comparitech.com/blog/information-security/thai-t... [2] https://github.com/docker/for-linux/issues/690 https://github.com/docker/for-linux/issues/690